Security & privacy
Bank statements are among the most sensitive documents your customers will ever upload. Here's exactly what happens to them — in plain English, because BFSI trust is earned with specifics, not badges.
Encryption
- TLS on every connection — web app and API. HSTS enabled; no plaintext fallback.
- Password-protected PDFs are unlocked in memory only — the password is never written to disk, logs, or the database.
- Uploads and outputs live on our own server only long enough to process and download them.
Retention & deletion
- Uploaded statements and generated files are deleted automatically after 24 hours.
- Analyzer previews are not persisted — the report lives in your browser.
- Nothing you upload is used to train models, and statement data is never sold.
Data handling
- Files are processed on our own host. There are no advertising trackers on this site.
- Optional AI verification (Google Gemini) runs only on OCR files or when balances fail to reconcile — and only the statement text needed for verification is sent. Digital statements that reconcile skip it entirely.
- By default the tools are anonymous: a session cookie lets this browser see its own conversions. If you create an account for larger files, we store your email and a salted, hashed password — never the password itself.
What we don't claim
- We're not a credit bureau and don't make lending decisions — you do, using these signals plus your own policy.
- We don't display certifications we haven't earned. No SOC 2 badge, no ISO logo.
- We don't offer an API, webhooks, or stored analysis history beyond the 24-hour window described here.
- Review the output before you rely on it; most anomalies have perfectly legitimate explanations.